Manager - Zero Trust

Johnson ControlsPune, MaharashtraOn-siteFull-timeStaff, 8–12 yearsListed 1 hour ago

Apply now

About this role

Job Code:

Job Code Name:

Business Title: Manager – Zero Trust

Region: APAC – Bengaluru/Pune

Country: India

Grade: 175

What you will do

As Manager – Zero Trust, you will own the Zero Trust strategy and roadmap, aligned to NIST SP 800-207 and the CISA Zero Trust Maturity Model. You will drive measurable removal of implicit trust across identity, devices, networks, applications and data, and approve the designs that go to production. You will lead and grow a multi-disciplinary team through structured Zero Trust training, clear performance management and real delegation. You will deliver concurrent programs with sprint discipline, operational SLAs and audit readiness. You will also act as the organization's Zero Trust advocate with IT partners.

What we look for

Required

·       10+ years in cybersecurity, across network security, identity, cloud or security architecture, with meaningful hands-on depth rather than oversight only.

·       6+ years of direct people management. We mean line management with hiring, development, performance, retention and succession accountability, not technical leadership of a project team.

·       Practical Zero Trust experience in role. You have designed, implemented or led Zero Trust initiatives in an enterprise, and can describe what you changed, how you measured it and what went wrong.

·       Strong grounding in Zero Trust principles and frameworks, including NIST SP 800-207, the CISA Zero Trust Maturity Model or equivalent, and the judgment to apply them to a real, imperfect estate.

·       Working knowledge across several Zero Trust domains:

o   ZTNA and SSE/SASE

o   Microsegmentation

o   Identity and access management

o   Privileged access

o   Conditional access and MFA

o   Device trust

o   Application and developer-environment access

o   Data protection

·       Experience developing security strategies, architectures and roadmaps, and owning their delivery from design through build, operation and automation.

·       Enough technical depth to credibly review and challenge designs from senior network and identity engineers.

·       Experience leading the response to high-severity security incidents. This means coordinating IT, legal and business teams through containment, remediation and post-incident control improvement.

·       Experience building or scaling a team, not only inheriting one, including managing across regions and planning capacity.

·       Outstanding communication and presentation skills. You can explain complex technical concepts to non-technical audiences and defend a technical position to senior leadership.

Preferred

·       Zero Trust certification, such as the CSA Certificate of Competence in Zero Trust (CCZT), Forrester Zero Trust Strategist, or a vendor Zero Trust certification.

·       Broader security or architecture certification, such as CISSP, CCSP, CISM, SANS (GIAC) or TOGAF.

·       Hands-on experience with leading Zero Trust platforms, for example:

o   SSE/ZTNA: Zscaler or Netskope

o   Microsegmentation: Guardicore or Illumio

o   Identity and IDaaS: Microsoft Entra ID, Okta, Ping Identity or Google Cloud Identity

o   Identity governance: SailPoint, Saviynt or equivalent

o   Privileged access management

·       Network security background across on-premises and cloud:

o   On-premises: firewall policy and rule management, IDS/IPS, network access control, remote access VPN and internet proxies.

o   Cloud: cloud proxies, cloud web application firewall and API protection (WAF/WAAP), and Azure or GCP security services.

·       Cloud security posture management across multi-cloud environments (CSPM/CNAPP).

·       Security operations experience, including SIEM tools such as Splunk for log analysis and event correlation, and risk-based vulnerability management.

·       AI security experience, either securing enterprise use of AI or applying AI to security operations.

·       Exposure to OT and IoT security, including IEC 62443.

·       Automation experience, such as Python, PowerShell, low-code platforms or ITSM integration.

·       Experience in a large, regulated enterprise with a legacy estate, M&A activity and real technical debt.

·       Working knowledge of security and regulatory frameworks, such as NIST CSF, ISO/IEC 27001, SOX, PCI DSS, GDPR and HIPAA.

Johnson Controls International plc. is an equal employment opportunity and affirmative action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, protected veteran status, genetic information, status as a qualified individual with a disability, or any other characteristic protected by law. For more information, please view EEO is the Law . If you are an individual with a disability and you require an accommodation during the application process, please visit www.johnsoncontrols.com/careers .